HTTP response splitting in axios - CVE-2026-42035
Published: April 24, 2026 / Updated: June 18, 2026
Vulnerability details
The vulnerability allows a remote attacker to inject arbitrary HTTP headers into outgoing requests.
The vulnerability exists due to improper neutralization of CRLF sequences in HTTP headers in lib/adapters/http.js when processing data payloads in HTTP requests after a polluted object prototype causes plain objects to be treated as FormData instances. A remote attacker can pollute Object.prototype so that an attacker-controlled getHeaders() function is invoked to inject arbitrary HTTP headers into outgoing requests.
Exploitation requires a prototype pollution primitive somewhere in the application's dependency chain and the application must use Axios to send requests with a data payload such as POST, PUT, or PATCH.
Affected software
IBM Cloud Pak System
IBM MQ Operator
Jira Service Management Data Center
Confluence Data Center
Bitbucket Data Center
Jira Software Data Center
Bamboo Data Center
IBM Decision Optimization for Cloud Pak for Data
IBM supplied MQ Advanced container images
Fedora
nextcloud
How to mitigate CVE-2026-42035
IBM Cloud Pak System - update to 2.3.5.1
IBM MQ Operator - addressed in versions 3.2.26 SC2, 4.0.1 SC2
Jira Service Management Data Center - addressed in versions 10.3.22, 11.3.7
Confluence Data Center - addressed in versions 9.2.22, 10.2.14
IBM supplied MQ Advanced container images - update to 10.0.0.0-r2
Bitbucket Data Center - addressed in versions 9.4.21, 10.2.4, 10.3.1
Jira Software Data Center - addressed in versions 10.3.22, 11.3.7
Bamboo Data Center - addressed in versions 10.2.20, 12.1.8
IBM Decision Optimization for Cloud Pak for Data - update to 5.3.1 patch 6
nextcloud - addressed in versions 33.0.3-1.el10_2, 33.0.3-1.el10_3, 33.0.3-1.fc42, 33.0.3-1.fc43, 33.0.3-1.fc44
External References
Related Security Bulletins
- Multiple vulnerabilities in axios
- Fedora 44 update for nextcloud
- Fedora 43 update for nextcloud
- Fedora EPEL 10.3 update for nextcloud
- Fedora EPEL 10.2 update for nextcloud
- Fedora 42 update for nextcloud
- Multiple vulnerabilities in Bamboo Data Center
- Multiple vulnerabilities in Bitbucket Data Center
- Multiple vulnerabilities in Jira Service Management Data Center and Jira Service Management Server
- Multiple vulnerabilities in Jira Software Data Center
- Multiple vulnerabilities in IBM Decision Optimization for Cloud Pak for Data
- Multiple vulnerabilities in IBM Cloud Pak System
- Multiple vulnerabilities in IBM MQ Operator and Queue manager container images
- Multiple vulnerabilities in Confluence Data Center